Home | History | Annotate | Line # | Download | only in sys
t_setrlimit.c revision 1.5
      1  1.5     njoly /* $NetBSD: t_setrlimit.c,v 1.5 2016/07/13 09:53:16 njoly Exp $ */
      2  1.1    jruoho 
      3  1.1    jruoho /*-
      4  1.1    jruoho  * Copyright (c) 2011 The NetBSD Foundation, Inc.
      5  1.1    jruoho  * All rights reserved.
      6  1.1    jruoho  *
      7  1.1    jruoho  * This code is derived from software contributed to The NetBSD Foundation
      8  1.1    jruoho  * by Jukka Ruohonen.
      9  1.1    jruoho  *
     10  1.1    jruoho  * Redistribution and use in source and binary forms, with or without
     11  1.1    jruoho  * modification, are permitted provided that the following conditions
     12  1.1    jruoho  * are met:
     13  1.1    jruoho  * 1. Redistributions of source code must retain the above copyright
     14  1.1    jruoho  *    notice, this list of conditions and the following disclaimer.
     15  1.1    jruoho  * 2. Redistributions in binary form must reproduce the above copyright
     16  1.1    jruoho  *    notice, this list of conditions and the following disclaimer in the
     17  1.1    jruoho  *    documentation and/or other materials provided with the distribution.
     18  1.1    jruoho  *
     19  1.1    jruoho  * THIS SOFTWARE IS PROVIDED BY THE NETBSD FOUNDATION, INC. AND CONTRIBUTORS
     20  1.1    jruoho  * ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED
     21  1.1    jruoho  * TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
     22  1.1    jruoho  * PURPOSE ARE DISCLAIMED.  IN NO EVENT SHALL THE FOUNDATION OR CONTRIBUTORS
     23  1.1    jruoho  * BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
     24  1.1    jruoho  * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
     25  1.1    jruoho  * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
     26  1.1    jruoho  * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
     27  1.1    jruoho  * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
     28  1.1    jruoho  * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
     29  1.1    jruoho  * POSSIBILITY OF SUCH DAMAGE.
     30  1.1    jruoho  */
     31  1.1    jruoho #include <sys/cdefs.h>
     32  1.5     njoly __RCSID("$NetBSD: t_setrlimit.c,v 1.5 2016/07/13 09:53:16 njoly Exp $");
     33  1.1    jruoho 
     34  1.1    jruoho #include <sys/resource.h>
     35  1.1    jruoho #include <sys/mman.h>
     36  1.1    jruoho #include <sys/wait.h>
     37  1.1    jruoho 
     38  1.1    jruoho #include <atf-c.h>
     39  1.1    jruoho #include <errno.h>
     40  1.1    jruoho #include <fcntl.h>
     41  1.1    jruoho #include <limits.h>
     42  1.4  christos #include <lwp.h>
     43  1.1    jruoho #include <signal.h>
     44  1.2  dholland #include <stdint.h>
     45  1.4  christos #include <stdio.h>
     46  1.1    jruoho #include <stdlib.h>
     47  1.1    jruoho #include <string.h>
     48  1.4  christos #include <ucontext.h>
     49  1.1    jruoho #include <unistd.h>
     50  1.1    jruoho 
     51  1.1    jruoho static void		 sighandler(int);
     52  1.1    jruoho static const char	 path[] = "setrlimit";
     53  1.1    jruoho 
     54  1.1    jruoho static const int rlimit[] = {
     55  1.1    jruoho 	RLIMIT_AS,
     56  1.1    jruoho 	RLIMIT_CORE,
     57  1.1    jruoho 	RLIMIT_CPU,
     58  1.1    jruoho 	RLIMIT_DATA,
     59  1.1    jruoho 	RLIMIT_FSIZE,
     60  1.1    jruoho 	RLIMIT_MEMLOCK,
     61  1.1    jruoho 	RLIMIT_NOFILE,
     62  1.1    jruoho 	RLIMIT_NPROC,
     63  1.1    jruoho 	RLIMIT_RSS,
     64  1.1    jruoho 	RLIMIT_SBSIZE,
     65  1.1    jruoho 	RLIMIT_STACK
     66  1.1    jruoho };
     67  1.1    jruoho 
     68  1.1    jruoho ATF_TC(setrlimit_basic);
     69  1.1    jruoho ATF_TC_HEAD(setrlimit_basic, tc)
     70  1.1    jruoho {
     71  1.1    jruoho 	atf_tc_set_md_var(tc, "descr", "A basic soft limit test");
     72  1.1    jruoho }
     73  1.1    jruoho 
     74  1.1    jruoho ATF_TC_BODY(setrlimit_basic, tc)
     75  1.1    jruoho {
     76  1.1    jruoho 	struct rlimit res;
     77  1.1    jruoho 	int *buf, lim;
     78  1.1    jruoho 	size_t i;
     79  1.1    jruoho 
     80  1.1    jruoho 	buf = calloc(__arraycount(rlimit), sizeof(int));
     81  1.1    jruoho 
     82  1.1    jruoho 	if (buf == NULL)
     83  1.1    jruoho 		atf_tc_fail("initialization failed");
     84  1.1    jruoho 
     85  1.1    jruoho 	for (i = lim = 0; i < __arraycount(rlimit); i++) {
     86  1.1    jruoho 
     87  1.1    jruoho 		(void)memset(&res, 0, sizeof(struct rlimit));
     88  1.1    jruoho 
     89  1.1    jruoho 		if (getrlimit(rlimit[i], &res) != 0)
     90  1.1    jruoho 			continue;
     91  1.1    jruoho 
     92  1.1    jruoho 		if (res.rlim_cur == RLIM_INFINITY || res.rlim_cur == 0)
     93  1.1    jruoho 			continue;
     94  1.1    jruoho 
     95  1.1    jruoho 		if (res.rlim_cur == res.rlim_max) /* An unprivileged run. */
     96  1.1    jruoho 			continue;
     97  1.1    jruoho 
     98  1.1    jruoho 		buf[i] = res.rlim_cur;
     99  1.1    jruoho 		res.rlim_cur = res.rlim_cur - 1;
    100  1.1    jruoho 
    101  1.1    jruoho 		if (setrlimit(rlimit[i], &res) != 0) {
    102  1.1    jruoho 			lim = rlimit[i];
    103  1.1    jruoho 			goto out;
    104  1.1    jruoho 		}
    105  1.1    jruoho 	}
    106  1.1    jruoho 
    107  1.1    jruoho out:
    108  1.1    jruoho 	for (i = 0; i < __arraycount(rlimit); i++) {
    109  1.1    jruoho 
    110  1.1    jruoho 		(void)memset(&res, 0, sizeof(struct rlimit));
    111  1.1    jruoho 
    112  1.1    jruoho 		if (buf[i] == 0)
    113  1.1    jruoho 			continue;
    114  1.1    jruoho 
    115  1.1    jruoho 		if (getrlimit(rlimit[i], &res) != 0)
    116  1.1    jruoho 			continue;
    117  1.1    jruoho 
    118  1.1    jruoho 		res.rlim_cur = buf[i];
    119  1.1    jruoho 
    120  1.1    jruoho 		(void)setrlimit(rlimit[i], &res);
    121  1.1    jruoho 	}
    122  1.1    jruoho 
    123  1.1    jruoho 	if (lim != 0)
    124  1.1    jruoho 		atf_tc_fail("failed to set limit (%d)", lim);
    125  1.1    jruoho }
    126  1.1    jruoho 
    127  1.1    jruoho ATF_TC(setrlimit_current);
    128  1.1    jruoho ATF_TC_HEAD(setrlimit_current, tc)
    129  1.1    jruoho {
    130  1.1    jruoho 	atf_tc_set_md_var(tc, "descr", "setrlimit(3) with current limits");
    131  1.1    jruoho }
    132  1.1    jruoho 
    133  1.1    jruoho ATF_TC_BODY(setrlimit_current, tc)
    134  1.1    jruoho {
    135  1.1    jruoho 	struct rlimit res;
    136  1.1    jruoho 	size_t i;
    137  1.1    jruoho 
    138  1.1    jruoho 	for (i = 0; i < __arraycount(rlimit); i++) {
    139  1.1    jruoho 
    140  1.1    jruoho 		(void)memset(&res, 0, sizeof(struct rlimit));
    141  1.1    jruoho 
    142  1.1    jruoho 		ATF_REQUIRE(getrlimit(rlimit[i], &res) == 0);
    143  1.1    jruoho 		ATF_REQUIRE(setrlimit(rlimit[i], &res) == 0);
    144  1.1    jruoho 	}
    145  1.1    jruoho }
    146  1.1    jruoho 
    147  1.1    jruoho ATF_TC(setrlimit_err);
    148  1.1    jruoho ATF_TC_HEAD(setrlimit_err, tc)
    149  1.1    jruoho {
    150  1.1    jruoho 	atf_tc_set_md_var(tc, "descr", "Test error conditions");
    151  1.1    jruoho }
    152  1.1    jruoho 
    153  1.1    jruoho ATF_TC_BODY(setrlimit_err, tc)
    154  1.1    jruoho {
    155  1.1    jruoho 	struct rlimit res;
    156  1.1    jruoho 	size_t i;
    157  1.1    jruoho 
    158  1.1    jruoho 	for (i = 0; i < __arraycount(rlimit); i++) {
    159  1.1    jruoho 
    160  1.1    jruoho 		errno = 0;
    161  1.1    jruoho 
    162  1.1    jruoho 		ATF_REQUIRE(getrlimit(rlimit[i], (void *)0) != 0);
    163  1.1    jruoho 		ATF_REQUIRE(errno == EFAULT);
    164  1.1    jruoho 	}
    165  1.1    jruoho 
    166  1.1    jruoho 	errno = 0;
    167  1.1    jruoho 
    168  1.1    jruoho 	ATF_REQUIRE(getrlimit(INT_MAX, &res) != 0);
    169  1.1    jruoho 	ATF_REQUIRE(errno == EINVAL);
    170  1.1    jruoho }
    171  1.1    jruoho 
    172  1.1    jruoho ATF_TC_WITH_CLEANUP(setrlimit_fsize);
    173  1.1    jruoho ATF_TC_HEAD(setrlimit_fsize, tc)
    174  1.1    jruoho {
    175  1.1    jruoho 	atf_tc_set_md_var(tc, "descr", "Test setrlimit(2), RLIMIT_FSIZE");
    176  1.1    jruoho }
    177  1.1    jruoho 
    178  1.1    jruoho ATF_TC_BODY(setrlimit_fsize, tc)
    179  1.1    jruoho {
    180  1.1    jruoho 	struct rlimit res;
    181  1.1    jruoho 	int fd, sta;
    182  1.1    jruoho 	pid_t pid;
    183  1.1    jruoho 
    184  1.1    jruoho 	fd = open(path, O_RDWR | O_CREAT, 0700);
    185  1.1    jruoho 
    186  1.1    jruoho 	if (fd < 0)
    187  1.1    jruoho 		atf_tc_fail("initialization failed");
    188  1.1    jruoho 
    189  1.1    jruoho 	pid = fork();
    190  1.1    jruoho 	ATF_REQUIRE(pid >= 0);
    191  1.1    jruoho 
    192  1.1    jruoho 	if (pid == 0) {
    193  1.1    jruoho 
    194  1.1    jruoho 		res.rlim_cur = 2;
    195  1.1    jruoho 		res.rlim_max = 2;
    196  1.1    jruoho 
    197  1.1    jruoho 		if (setrlimit(RLIMIT_FSIZE, &res) != 0)
    198  1.1    jruoho 			_exit(EXIT_FAILURE);
    199  1.1    jruoho 
    200  1.1    jruoho 		if (signal(SIGXFSZ, sighandler) == SIG_ERR)
    201  1.1    jruoho 			_exit(EXIT_FAILURE);
    202  1.1    jruoho 
    203  1.1    jruoho 		/*
    204  1.1    jruoho 		 * The third call should generate a SIGXFSZ.
    205  1.1    jruoho 		 */
    206  1.1    jruoho 		(void)write(fd, "X", 1);
    207  1.1    jruoho 		(void)write(fd, "X", 1);
    208  1.1    jruoho 		(void)write(fd, "X", 1);
    209  1.1    jruoho 
    210  1.1    jruoho 		_exit(EXIT_FAILURE);
    211  1.1    jruoho 	}
    212  1.1    jruoho 
    213  1.1    jruoho 	(void)close(fd);
    214  1.1    jruoho 	(void)wait(&sta);
    215  1.1    jruoho 	(void)unlink(path);
    216  1.1    jruoho 
    217  1.1    jruoho 	if (WIFEXITED(sta) == 0 || WEXITSTATUS(sta) != EXIT_SUCCESS)
    218  1.1    jruoho 		atf_tc_fail("RLIMIT_FSIZE not enforced");
    219  1.1    jruoho }
    220  1.1    jruoho 
    221  1.1    jruoho ATF_TC_CLEANUP(setrlimit_fsize, tc)
    222  1.1    jruoho {
    223  1.1    jruoho 	(void)unlink(path);
    224  1.1    jruoho }
    225  1.1    jruoho 
    226  1.1    jruoho static void
    227  1.1    jruoho sighandler(int signo)
    228  1.1    jruoho {
    229  1.1    jruoho 
    230  1.1    jruoho 	if (signo != SIGXFSZ)
    231  1.1    jruoho 		_exit(EXIT_FAILURE);
    232  1.1    jruoho 
    233  1.1    jruoho 	_exit(EXIT_SUCCESS);
    234  1.1    jruoho }
    235  1.1    jruoho 
    236  1.1    jruoho ATF_TC(setrlimit_memlock);
    237  1.1    jruoho ATF_TC_HEAD(setrlimit_memlock, tc)
    238  1.1    jruoho {
    239  1.1    jruoho 	atf_tc_set_md_var(tc, "descr", "Test setrlimit(2), RLIMIT_MEMLOCK");
    240  1.1    jruoho }
    241  1.1    jruoho 
    242  1.1    jruoho ATF_TC_BODY(setrlimit_memlock, tc)
    243  1.1    jruoho {
    244  1.1    jruoho 	struct rlimit res;
    245  1.1    jruoho 	void *buf;
    246  1.1    jruoho 	long page;
    247  1.1    jruoho 	pid_t pid;
    248  1.1    jruoho 	int sta;
    249  1.1    jruoho 
    250  1.1    jruoho 	page = sysconf(_SC_PAGESIZE);
    251  1.1    jruoho 	ATF_REQUIRE(page >= 0);
    252  1.1    jruoho 
    253  1.1    jruoho 	buf = malloc(page);
    254  1.1    jruoho 	pid = fork();
    255  1.1    jruoho 
    256  1.1    jruoho 	if (buf == NULL || pid < 0)
    257  1.1    jruoho 		atf_tc_fail("initialization failed");
    258  1.1    jruoho 
    259  1.1    jruoho 	if (pid == 0) {
    260  1.1    jruoho 
    261  1.1    jruoho 		/*
    262  1.1    jruoho 		 * Try to lock a page while
    263  1.1    jruoho 		 * RLIMIT_MEMLOCK is zero.
    264  1.1    jruoho 		 */
    265  1.1    jruoho 		if (mlock(buf, page) != 0)
    266  1.1    jruoho 			_exit(EXIT_FAILURE);
    267  1.1    jruoho 
    268  1.1    jruoho 		if (munlock(buf, page) != 0)
    269  1.1    jruoho 			_exit(EXIT_FAILURE);
    270  1.1    jruoho 
    271  1.1    jruoho 		res.rlim_cur = 0;
    272  1.1    jruoho 		res.rlim_max = 0;
    273  1.1    jruoho 
    274  1.1    jruoho 		if (setrlimit(RLIMIT_MEMLOCK, &res) != 0)
    275  1.1    jruoho 			_exit(EXIT_FAILURE);
    276  1.1    jruoho 
    277  1.1    jruoho 		if (mlock(buf, page) != 0)
    278  1.1    jruoho 			_exit(EXIT_SUCCESS);
    279  1.1    jruoho 
    280  1.1    jruoho 		(void)munlock(buf, page);
    281  1.1    jruoho 
    282  1.1    jruoho 		_exit(EXIT_FAILURE);
    283  1.1    jruoho 	}
    284  1.1    jruoho 
    285  1.1    jruoho 	free(buf);
    286  1.1    jruoho 
    287  1.1    jruoho 	(void)wait(&sta);
    288  1.1    jruoho 
    289  1.1    jruoho 	if (WIFEXITED(sta) == 0 || WEXITSTATUS(sta) != EXIT_SUCCESS)
    290  1.1    jruoho 		atf_tc_fail("RLIMIT_MEMLOCK not enforced");
    291  1.1    jruoho }
    292  1.1    jruoho 
    293  1.1    jruoho ATF_TC(setrlimit_nofile_1);
    294  1.1    jruoho ATF_TC_HEAD(setrlimit_nofile_1, tc)
    295  1.1    jruoho {
    296  1.1    jruoho 	atf_tc_set_md_var(tc, "descr", "Test setrlimit(2), RLIMIT_NOFILE, #1");
    297  1.1    jruoho }
    298  1.1    jruoho 
    299  1.1    jruoho ATF_TC_BODY(setrlimit_nofile_1, tc)
    300  1.1    jruoho {
    301  1.1    jruoho 	struct rlimit res;
    302  1.1    jruoho 	int fd, i, rv, sta;
    303  1.1    jruoho 	pid_t pid;
    304  1.1    jruoho 
    305  1.1    jruoho 	res.rlim_cur = 0;
    306  1.1    jruoho 	res.rlim_max = 0;
    307  1.1    jruoho 
    308  1.1    jruoho 	pid = fork();
    309  1.1    jruoho 	ATF_REQUIRE(pid >= 0);
    310  1.1    jruoho 
    311  1.1    jruoho 	if (pid == 0) {
    312  1.1    jruoho 
    313  1.1    jruoho 		/*
    314  1.1    jruoho 		 * Close all descriptors, set RLIMIT_NOFILE
    315  1.1    jruoho 		 * to zero, and try to open a random file.
    316  1.1    jruoho 		 * This should fail with EMFILE.
    317  1.1    jruoho 		 */
    318  1.1    jruoho 		for (i = 0; i < 1024; i++)
    319  1.1    jruoho 			(void)close(i);
    320  1.1    jruoho 
    321  1.1    jruoho 		rv = setrlimit(RLIMIT_NOFILE, &res);
    322  1.1    jruoho 
    323  1.1    jruoho 		if (rv != 0)
    324  1.1    jruoho 			_exit(EXIT_FAILURE);
    325  1.1    jruoho 
    326  1.1    jruoho 		errno = 0;
    327  1.1    jruoho 		fd = open("/etc/passwd", O_RDONLY);
    328  1.1    jruoho 
    329  1.1    jruoho 		if (fd >= 0 || errno != EMFILE)
    330  1.1    jruoho 			_exit(EXIT_FAILURE);
    331  1.1    jruoho 
    332  1.1    jruoho 		_exit(EXIT_SUCCESS);
    333  1.1    jruoho 	}
    334  1.1    jruoho 
    335  1.1    jruoho 	(void)wait(&sta);
    336  1.1    jruoho 
    337  1.1    jruoho 	if (WIFEXITED(sta) == 0 || WEXITSTATUS(sta) != EXIT_SUCCESS)
    338  1.1    jruoho 		atf_tc_fail("RLIMIT_NOFILE not enforced");
    339  1.1    jruoho }
    340  1.1    jruoho 
    341  1.1    jruoho ATF_TC(setrlimit_nofile_2);
    342  1.1    jruoho ATF_TC_HEAD(setrlimit_nofile_2, tc)
    343  1.1    jruoho {
    344  1.1    jruoho 	atf_tc_set_md_var(tc, "descr", "Test setrlimit(2), RLIMIT_NOFILE, #2");
    345  1.1    jruoho }
    346  1.1    jruoho 
    347  1.1    jruoho ATF_TC_BODY(setrlimit_nofile_2, tc)
    348  1.1    jruoho {
    349  1.1    jruoho 	static const rlim_t lim = 12;
    350  1.1    jruoho 	struct rlimit res;
    351  1.1    jruoho 	int fd, i, rv, sta;
    352  1.1    jruoho 	pid_t pid;
    353  1.1    jruoho 
    354  1.1    jruoho 	/*
    355  1.1    jruoho 	 * See that an arbitrary limit on
    356  1.1    jruoho 	 * open files is being enforced.
    357  1.1    jruoho 	 */
    358  1.1    jruoho 	res.rlim_cur = lim;
    359  1.1    jruoho 	res.rlim_max = lim;
    360  1.1    jruoho 
    361  1.1    jruoho 	pid = fork();
    362  1.1    jruoho 	ATF_REQUIRE(pid >= 0);
    363  1.1    jruoho 
    364  1.1    jruoho 	if (pid == 0) {
    365  1.1    jruoho 
    366  1.1    jruoho 		for (i = 0; i < 1024; i++)
    367  1.1    jruoho 			(void)close(i);
    368  1.1    jruoho 
    369  1.1    jruoho 		rv = setrlimit(RLIMIT_NOFILE, &res);
    370  1.1    jruoho 
    371  1.1    jruoho 		if (rv != 0)
    372  1.1    jruoho 			_exit(EXIT_FAILURE);
    373  1.1    jruoho 
    374  1.1    jruoho 		for (i = 0; i < (int)lim; i++) {
    375  1.1    jruoho 
    376  1.1    jruoho 			fd = open("/etc/passwd", O_RDONLY);
    377  1.1    jruoho 
    378  1.1    jruoho 			if (fd < 0)
    379  1.1    jruoho 				_exit(EXIT_FAILURE);
    380  1.1    jruoho 		}
    381  1.1    jruoho 
    382  1.1    jruoho 		/*
    383  1.1    jruoho 		 * After the limit has been reached,
    384  1.1    jruoho 		 * EMFILE should again follow.
    385  1.1    jruoho 		 */
    386  1.1    jruoho 		fd = open("/etc/passwd", O_RDONLY);
    387  1.1    jruoho 
    388  1.1    jruoho 		if (fd >= 0 || errno != EMFILE)
    389  1.1    jruoho 			_exit(EXIT_FAILURE);
    390  1.1    jruoho 
    391  1.1    jruoho 		_exit(EXIT_SUCCESS);
    392  1.1    jruoho 	}
    393  1.1    jruoho 
    394  1.1    jruoho 	(void)wait(&sta);
    395  1.1    jruoho 
    396  1.1    jruoho 	if (WIFEXITED(sta) == 0 || WEXITSTATUS(sta) != EXIT_SUCCESS)
    397  1.1    jruoho 		atf_tc_fail("RLIMIT_NOFILE not enforced");
    398  1.1    jruoho }
    399  1.1    jruoho 
    400  1.1    jruoho ATF_TC(setrlimit_nproc);
    401  1.1    jruoho ATF_TC_HEAD(setrlimit_nproc, tc)
    402  1.1    jruoho {
    403  1.1    jruoho 	atf_tc_set_md_var(tc, "descr", "Test setrlimit(2), RLIMIT_NPROC");
    404  1.1    jruoho 	atf_tc_set_md_var(tc, "require.user", "unprivileged");
    405  1.1    jruoho }
    406  1.1    jruoho 
    407  1.1    jruoho ATF_TC_BODY(setrlimit_nproc, tc)
    408  1.1    jruoho {
    409  1.1    jruoho 	struct rlimit res;
    410  1.1    jruoho 	pid_t pid, cpid;
    411  1.1    jruoho 	int sta;
    412  1.1    jruoho 
    413  1.1    jruoho 	pid = fork();
    414  1.1    jruoho 	ATF_REQUIRE(pid >= 0);
    415  1.1    jruoho 
    416  1.1    jruoho 	if (pid == 0) {
    417  1.1    jruoho 
    418  1.1    jruoho 		/*
    419  1.1    jruoho 		 * Set RLIMIT_NPROC to zero and try to fork.
    420  1.1    jruoho 		 */
    421  1.1    jruoho 		res.rlim_cur = 0;
    422  1.1    jruoho 		res.rlim_max = 0;
    423  1.1    jruoho 
    424  1.1    jruoho 		if (setrlimit(RLIMIT_NPROC, &res) != 0)
    425  1.1    jruoho 			_exit(EXIT_FAILURE);
    426  1.1    jruoho 
    427  1.1    jruoho 		cpid = fork();
    428  1.1    jruoho 
    429  1.1    jruoho 		if (cpid < 0)
    430  1.1    jruoho 			_exit(EXIT_SUCCESS);
    431  1.1    jruoho 
    432  1.1    jruoho 		_exit(EXIT_FAILURE);
    433  1.1    jruoho 	}
    434  1.1    jruoho 
    435  1.1    jruoho 	(void)waitpid(pid, &sta, 0);
    436  1.1    jruoho 
    437  1.1    jruoho 	if (WIFEXITED(sta) == 0 || WEXITSTATUS(sta) != EXIT_SUCCESS)
    438  1.1    jruoho 		atf_tc_fail("RLIMIT_NPROC not enforced");
    439  1.1    jruoho }
    440  1.1    jruoho 
    441  1.4  christos ATF_TC(setrlimit_nthr);
    442  1.4  christos ATF_TC_HEAD(setrlimit_nthr, tc)
    443  1.4  christos {
    444  1.4  christos 	atf_tc_set_md_var(tc, "descr", "Test setrlimit(2), RLIMIT_NTHR");
    445  1.4  christos 	atf_tc_set_md_var(tc, "require.user", "unprivileged");
    446  1.4  christos }
    447  1.4  christos 
    448  1.4  christos static void
    449  1.4  christos func(lwpid_t *id)
    450  1.4  christos {
    451  1.4  christos 	printf("thread %d\n", *id);
    452  1.4  christos 	fflush(stdout);
    453  1.4  christos 	_lwp_exit();
    454  1.4  christos }
    455  1.4  christos 
    456  1.4  christos ATF_TC_BODY(setrlimit_nthr, tc)
    457  1.4  christos {
    458  1.4  christos 	struct rlimit res;
    459  1.4  christos 	lwpid_t lwpid;
    460  1.4  christos 	ucontext_t c;
    461  1.4  christos 
    462  1.4  christos 	/*
    463  1.4  christos 	 * Set RLIMIT_NTHR to zero and try to create a thread.
    464  1.4  christos 	 */
    465  1.4  christos 	res.rlim_cur = 0;
    466  1.4  christos 	res.rlim_max = 0;
    467  1.4  christos 	ATF_REQUIRE(setrlimit(RLIMIT_NTHR, &res) == 0);
    468  1.4  christos 	ATF_REQUIRE(getcontext(&c) == 0);
    469  1.4  christos 	c.uc_link = NULL;
    470  1.4  christos 	sigemptyset(&c.uc_sigmask);
    471  1.4  christos 	c.uc_stack.ss_flags = 0;
    472  1.4  christos 	c.uc_stack.ss_size = 4096;
    473  1.4  christos 	ATF_REQUIRE((c.uc_stack.ss_sp = malloc(c.uc_stack.ss_size)) != NULL);
    474  1.4  christos 	makecontext(&c, func, 1, &lwpid);
    475  1.4  christos 	ATF_CHECK_ERRNO(EAGAIN, _lwp_create(&c, 0, &lwpid) == -1);
    476  1.4  christos }
    477  1.4  christos 
    478  1.1    jruoho ATF_TC(setrlimit_perm);
    479  1.1    jruoho ATF_TC_HEAD(setrlimit_perm, tc)
    480  1.1    jruoho {
    481  1.1    jruoho 	atf_tc_set_md_var(tc, "descr", "Test setrlimit(2) for EPERM");
    482  1.1    jruoho 	atf_tc_set_md_var(tc, "require.user", "unprivileged");
    483  1.1    jruoho }
    484  1.1    jruoho 
    485  1.1    jruoho ATF_TC_BODY(setrlimit_perm, tc)
    486  1.1    jruoho {
    487  1.1    jruoho 	struct rlimit res;
    488  1.1    jruoho 	size_t i;
    489  1.1    jruoho 
    490  1.1    jruoho 	/*
    491  1.1    jruoho 	 * Try to raise the maximum limits as an user.
    492  1.1    jruoho 	 */
    493  1.1    jruoho 	for (i = 0; i < __arraycount(rlimit); i++) {
    494  1.1    jruoho 
    495  1.1    jruoho 		ATF_REQUIRE(getrlimit(rlimit[i], &res) == 0);
    496  1.1    jruoho 
    497  1.1    jruoho 		if (res.rlim_max == UINT64_MAX) /* Overflow. */
    498  1.1    jruoho 			continue;
    499  1.1    jruoho 
    500  1.1    jruoho 		errno = 0;
    501  1.1    jruoho 		res.rlim_max = res.rlim_max + 1;
    502  1.1    jruoho 
    503  1.3     njoly 		ATF_CHECK_ERRNO(EPERM, setrlimit(rlimit[i], &res) != 0);
    504  1.1    jruoho 	}
    505  1.1    jruoho }
    506  1.1    jruoho 
    507  1.5     njoly ATF_TC(setrlimit_stack);
    508  1.5     njoly ATF_TC_HEAD(setrlimit_stack, tc)
    509  1.5     njoly {
    510  1.5     njoly 	atf_tc_set_md_var(tc, "descr", "Test setrlimit(2), RLIMIT_STACK");
    511  1.5     njoly 	atf_tc_set_md_var(tc, "require.user", "unprivileged");
    512  1.5     njoly }
    513  1.5     njoly 
    514  1.5     njoly ATF_TC_BODY(setrlimit_stack, tc)
    515  1.5     njoly {
    516  1.5     njoly 	struct rlimit res;
    517  1.5     njoly 
    518  1.5     njoly 	/* Ensure soft limit is not bigger than hard limit */
    519  1.5     njoly 	res.rlim_cur = res.rlim_max = 4192256;
    520  1.5     njoly 	ATF_REQUIRE(setrlimit(RLIMIT_STACK, &res) == 0);
    521  1.5     njoly 	ATF_REQUIRE(getrlimit(RLIMIT_STACK, &res) == 0);
    522  1.5     njoly 	ATF_CHECK(res.rlim_cur <= res.rlim_max);
    523  1.5     njoly 
    524  1.5     njoly }
    525  1.5     njoly 
    526  1.1    jruoho ATF_TP_ADD_TCS(tp)
    527  1.1    jruoho {
    528  1.1    jruoho 
    529  1.1    jruoho 	ATF_TP_ADD_TC(tp, setrlimit_basic);
    530  1.1    jruoho 	ATF_TP_ADD_TC(tp, setrlimit_current);
    531  1.1    jruoho 	ATF_TP_ADD_TC(tp, setrlimit_err);
    532  1.1    jruoho 	ATF_TP_ADD_TC(tp, setrlimit_fsize);
    533  1.1    jruoho 	ATF_TP_ADD_TC(tp, setrlimit_memlock);
    534  1.1    jruoho 	ATF_TP_ADD_TC(tp, setrlimit_nofile_1);
    535  1.1    jruoho 	ATF_TP_ADD_TC(tp, setrlimit_nofile_2);
    536  1.1    jruoho 	ATF_TP_ADD_TC(tp, setrlimit_nproc);
    537  1.1    jruoho 	ATF_TP_ADD_TC(tp, setrlimit_perm);
    538  1.4  christos 	ATF_TP_ADD_TC(tp, setrlimit_nthr);
    539  1.5     njoly 	ATF_TP_ADD_TC(tp, setrlimit_stack);
    540  1.1    jruoho 
    541  1.1    jruoho 	return atf_no_error();
    542  1.1    jruoho }
    543